SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
88 breaches, 2.15 billion records, and 41 leaks that nobody can reset
A compiled timeline of identity-verification failures since 2011 puts nearly half the incidents in the category where what leaked was the face or the document itself.
The Watch · Security desk
What happened
- Mysterium VPN has published a timeline of 88 documented incidents since 2011 in which data collected to verify identity or age was breached, exposed or sold.
- The confirmed and researcher-verified total across those incidents is 2.15 billion records.
- Claims made by attackers and data sellers would add another 4.54 billion records that nobody has verified.
Why it matters
- constraint For nearly half the catalogued incidents there is no remediation step to fund: you cannot reissue a fingerprint, so the response ends at notification and monitoring.
- exposure Because AU10TIX sits in front of TikTok, Uber and X, an exposure at the vendor reaches those platforms' users, who never chose the vendor and cannot audit it.
- decision Firms adding age gates have to decide whether outsourcing transfers the liability or only the storage, and the timeline argues it does the latter.
- contradiction The headline volume depends on which figure you accept: verified counts and criminal boasts differ by billions, and only one of them belongs in a risk model.
The rate is the part the report leaves on the table. Thirty-seven of the 88 incidents fall inside the 32 months from January 2024 to August 2026 [7]. Treat the timeline as starting in January 2011 and the other 51 spread across roughly 156 months, which is about one incident a quarter in the older period against better than one a month in the recent one, a rate around three and a half times higher [18]. Some of that gap is an artefact of counting: a 2013 exposure is harder to find than a 2025 one. The rest is supply. Mandates create databases, and databases are what leave.
The concentration is the more useful detail for anyone buying this as a service. AU10TIX, which verifies identity for TikTok, Uber and X, left admin credentials exposed for more than a year [10]. Sumsub disclosed a support-system intrusion that ran undetected for 18 months [11]. Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration [12]. The report's claim is that every major vendor of this era appears somewhere in the timeline, naming AU10TIX, IDMerit, Sumsub, Persona and inVOID [1]. Outsourcing an age gate does not take the ID off your risk register. It moves the document into a company whose client list is the reason to attack it, and whose incidents you will hear about second.
Discord's case shows where the harm lands. The roughly 70,000 government IDs exposed through a third-party support provider belonged to users who had challenged an age-verification decision, meaning people who were trying to correct the system's judgement about them, and Discord carried on expanding age checks afterwards [9]. Tea, built as a women-only safety platform, lost verification selfies out of an open storage bucket, and the images later showed up on 4chan [8].
Government registries are in the same list at larger scale. Argentina's national identity system leaked 45 million records including ID scans and selfies [13], and France's ANTS, the agency that issues French identity documents, confirmed 11.7 million people affected in a 2026 breach [14]. Those two alone account for about 56.7 million [20], with India's Aadhaar, Thailand's visitor database, the Philippines' voter rolls and Brazil's tax registry also on the timeline [15].
Two cautions on the headline number. The compiler is a VPN company, Mysterium, which is worth holding in mind while reading its framing even though the incidents are individually checkable [3]. And the 4.54 billion attributed to attacker and seller claims is more than twice the verified figure [19], so the number to argue about is 2.15 billion [4]. The number to budget against is 41: the incidents where ID scans, verification selfies, fingerprints and biometric templates were part of what leaked, none of which can be reissued [6]. SecurityAffairs' reading is that leaning on a reputable third-party provider is not sufficient protection for firms weighing build against outsource [16], and the report's own conclusion is that this is one failure mode repeated across fifteen years and every type of organisation that decided to collect this category of data [2].
What to watch
- Whether regulators writing age-check mandates add retention limits or outright no-store rules for source documents and selfies.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence46
- Adoption62
- Hype gap+22
- Incentives71
- Confidence48
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The report states that every major identity-verification vendor of the current era, naming AU10TIX, IDMerit, Sumsub, Persona and inVOID, has appeared in its timeline.
ReportedSupportedSource: Mysterium VPN report, quoted by SecurityAffairs2 sources— create a free account to open themView cited source - [2]
The report concludes that the timeline shows one failure mode repeated across 88 incidents, fifteen years, and every type of organisation that has decided to collect this category of data.
ReportedSupportedSource: Mysterium VPN report, quoted by SecurityAffairs2 sources— create a free account to open themView cited source - [3]
A report from Mysterium VPN compiles 88 documented incidents since 2011 in which data collected specifically to verify someone's identity or age was breached, exposed, or sold.
- [4]
The confirmed and researcher-verified total across the 88 incidents is 2.15 billion records.
- [5]
Attacker and seller claims add a further 4.54 billion records on top of the verified total.
- [6]
In 41 of the 88 incidents, what leaked included the source documents themselves: ID scans, verification selfies, fingerprints and full biometric templates, none of which can be changed like a password.
- [7]
Of the 88 incidents, 37, or 42%, occurred between January 2024 and August 2026, while mandatory identity and age checks were spreading quickly around the world.
- [8]
The Tea app, created as a women-only safety platform, exposed verification selfies through an open storage bucket, and the images later appeared on 4chan.
- [9]
Discord users who challenged age-verification decisions had around 70,000 government IDs exposed through a third-party support provider, and Discord continued expanding age checks.
- [10]
AU10TIX, which verifies identity for TikTok, Uber and X, left admin credentials exposed for over a year.
- [11]
Sumsub disclosed a support-system intrusion that went undetected for 18 months.
- [12]
Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration.
- [13]
Argentina's national identity system leaked 45 million records including ID scans and selfies.
- [14]
France's ANTS, the agency that issues French identity documents, confirmed 11.7 million people affected in a 2026 breach.
- [15]
India's Aadhaar system, Thailand's visitor database, the Philippines' voter rolls and Brazil's tax registry also appear in the timeline.
- [16]
SecurityAffairs writes that companies deciding whether to build or outsource these systems should study the history, and that relying on a reputable third-party provider clearly is not enough.
- [17]
The incidents that leaked documents or biometrics are about 47% of the total, so nearly half of the catalogued breaches involve data that cannot be reissued.
- [18]
The 51 incidents before 2024 average about 0.33 per month, against about 1.16 per month for the 37 incidents from January 2024 to August 2026, a rate roughly three and a half times higher.
- [19]
The unverified attacker and seller claims are about 2.1 times the verified record count, and the combined figure would be 6.69 billion.
- [20]
The Argentine and French national identity incidents together account for about 56.7 million records or people.
Sources
1 independent publisher whose own reporting we read for this story.
- securityaffairs.com88 ID Verification Breaches Show the Cost of Collecting Identity Data
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Identity VerificationFollow
- Age VerificationFollow
- Biometric Data RiskFollow
- Third-Party and Supply Chain RiskFollow
- Data BreachesFollow
- National Identity RegistriesFollow